Kaspersky researchers discovered Keenadu, a sophisticated Android backdoor embedded in tablet firmware that compromises every app on infected devices. The malware injects itself into the Zygote process through a compromised libandroid_runtime.so library, likely introduced via supply chain attack during firmware builds. Keenadu
Table of contents
Malicious dropper in libandroid_runtime.soHow Keenadu compromised libandroid_runtime.soKeenadu backdoor modulesOther Keenadu distribution vectorsThe Fantastic Four: how Triada, BADBOX, Vo1d, and Keenadu are connectedVictimsRecommendationsConclusionIndicators of compromiseSort: